cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
16510
Views
0
Helpful
2
Replies

Disable SSH Weak Ciphers

rab ngl
Level 1
Level 1

We noticed that the SSH server of Cisco ESA is configured to use the weak encryption algorithms (arcfour, arcfour128 & arcfour256, cbc) and mac algorithms (hmac-sha1 and hmac-md5).

 

My question is:

 

How to disable SHA1 key algorithms?

How to disable CBC mode ciphers and use CTR mode ciphers?

How to disable 96-bit HMAC Algorithms?

 

 

Thanks.

2 Accepted Solutions

Accepted Solutions

Libin Varghese
Cisco Employee
Cisco Employee

You can modify the ciphers in use from the command line of the appliance using command "sshconfig".

 

- Libin V

View solution in original post

2 Replies 2

Libin Varghese
Cisco Employee
Cisco Employee

You can modify the ciphers in use from the command line of the appliance using command "sshconfig".

 

- Libin V